Re: Samba

From: Brad Arlt (arlt_at_cpsc.ucalgary.ca)
Date: 11/27/03

  • Next message: Vishal: "Re: [off-topic] RE: Tow Cows for IT"
    Date: Thu, 27 Nov 2003 11:40:12 -0700
    To: Jack Solomon <solzjack43@hotmail.com>
    
    

    On Thu, Nov 27, 2003 at 03:16:42PM +0000, Jack Solomon wrote:
    > what are the security concerns over Samba? Someone told me that its
    > a real bad idea security-wise but noone can tell me why...

    Uhh... I'd imagine the samba team would argue otherwise :)

    If you need CIFS shares or SMB/SPOOLSS printing, I don't see how Samba
    is worse the Windows NT/2000/2003. You can at least chroot jail
    Samba...

    If you need a high degree of security you shouldn't use network
    filesharing. Not CODA, AFS, NFS, or CIFS. Network filesharing is
    very convinient and the forced convinience has led to some complexity
    of code that invariably results in bugs.

    Configure Samba proberly, and ensure you are running the latest bug
    corrected version, and you should be alright.
    -----------------------------------------------------------------------
       __o Bradley Arlt Security Team Lead
     _ \<_ arlt@cpsc.ucalgary.ca University Of Calgary
    (_)/(_) Joyously Canadian Computer Science

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Vishal: "Re: [off-topic] RE: Tow Cows for IT"

    Relevant Pages

    • [UNIX] Security Bugfix for Samba (SMB/CIFS Overflow)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... running a Samba server. ... The above will only allow SMB connections from 'localhost' (your own ... Fix delete on close semantics to match W2K. ...
      (Securiteam)
    • [UNIX] Buffer Overflow in Samba allows remote root compromise
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... off of the Samba source tree, and aims at being a substitute for a Windows ... A buffer overflow vulnerability in the Samba daemon allows an attacker to ...
      (Securiteam)
    • Re: CIFS on VMS, multi-user share per user security setup question
      ... and 'connects as another user' to log in to the samba ... When I added new sets of ACEs for the CIFS identifiers of each of the ... any other account had created. ... Another item is attempting to modify the security profile from the ...
      (comp.os.vms)
    • [UNIX] Samba Server Multiple Vulnerabilities
      ... Get your security news from a reliable source. ... Samba Server Multiple Vulnerabilities ... Buffer overrun in NSS host lookup Winbind library on Solaris: ...
      (Securiteam)
    • Re: Samba gives root rw access, but others only ro. Windows OK
      ... smb.conf until I had the security I needed. ... samba shares from the client. ... load printers = yes ... # Browser Control Options: ...
      (alt.os.linux.redhat)